Hide Forgot
Quick emulator(Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds r/w access issues. It could occur while copying VGA data via various bitblt functions. A privileged user inside guest could use this flaw to crash the Qemu process resulting in DoS OR potentially execute arbitrary code on a host with privileges of Qemu process on the host. Upstream patches: ----------------- -> http://git.qemu.org/?p=qemu.git;a=commitdiff;h=026aeffcb4752054830ba203020ed6eb05bcaba8 -> http://git.qemu.org/?p=qemu.git;a=commitdiff;h=ffaf857778286ca54e3804432a2369a279e73aa7 Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/04/21/1
Acknowledgments: Name: Jiangxin (PSIRT Huawei Inc.), Li Qiang (Qihoo 360 Gear Team)
Created xen tracking bugs for this issue: Affects: fedora-all [bug 1444373]
Created qemu tracking bugs for this issue: Affects: fedora-all [bug 1444372]
This issue has been addressed in the following products: RHEV 3.X Hypervisor and Agents for RHEL-6 Via RHSA-2017:1205 https://access.redhat.com/errata/RHSA-2017:1205
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2017:1206 https://access.redhat.com/errata/RHSA-2017:1206
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2017:1430 https://access.redhat.com/errata/RHSA-2017:1430
This issue has been addressed in the following products: Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 Via RHSA-2017:1441 https://access.redhat.com/errata/RHSA-2017:1441
qemu-2.7.1-7.fc25 has been pushed to the Fedora 25 stable repository. If problems still persist, please make note of it in this bug report.